The video is a removal guide of Philadelphia ransomware (Russian Roulette virus) and includes demonstration of virus, removing and decryption tips. It adds to txt, jpg, bmp and other files .locked extension and changes files names. <br />More information about Philadelphia virus: http://pcfixhelp.net/viruses/3627-how-to-remove-philadelphia-ransomware-and-restore-the-encrypted-files <br />Philadelphia ransomware removal instruction <br />Step 1. Boot the system into safe mode <br />Step 2. Show all hidden files and folders <br />Step 3. Remove virus files <br />Check next folders to find suspicious files: <br /> %TEMP% <br /> %APPDATA% <br /> %ProgramData% <br />Step 4 (optional). Clean registry <br /> Click Start <br /> Type Regedit.exe and press Enter <br /> Check next registry keys: <br /> HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\Run <br /> HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\RunOnce <br /> HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\RunServices <br /> HKEY_LOCAL_MACHINE(HKEY_CURRENT_USER)\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce <br /> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit <br />Step 5. Check hosts file <br />Step 6. Scan computer by antivirus <br />Step 7. Disable Safe mode <br /> <br />Emsisoft decryptor: https://decrypter.emsisoft.com/philadelphia